SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security

Hacker steals e-mail addresses, demands Astley tune

Hacker steals e-mail addresses, demands Astley tune

By:  Loek Essers  On: 19 May 2010 For: WebWereld Netherlands 

The Dutch hacker Darkc0ke was able to hack into the database of Dutch radio station 3FM and steal 22,000 e-mail addresses using a SQL injection attack. He threatened to publish the addresses unless the station played Rick Astley’s 'Never Gonna Give You Up'

Dutch hacker Darkc0ke hijacked a radio station database containing 22,000 e-mail addresses and threatened to publish them unless the station play Rick Astley's "Never Gonna Give You Up," a variation of an Internet meme known as "rickrolling."

 

Last weekend Darkc0ke mailed DJs from the Dutch nationwide radio station 3FM and issued his threat and demand. The disc jockeys notified the station's IT department, which realized that a backdoor to their database was indeed open.

 

"Of course, we did not comply" with the demand, said a 3FM spokeswoman. She confirmed that the database could be accessed and that Darkc0ke obtained the e-mail addresses. "We repaired the vulnerability as soon as possible." 3FM reported the hack to the police.

 

Darkc0ke said in various e-mail messages that he warned 3FM two weeks ago and pointed out the vulnerability to the station. He claims he never got an answer. 3FM's spokeswoman said the e-mail was not received.

 

Darkc0ke said he planned to publish the database contentthreads on Pastebin.com. In the end, he published the table of contents, but didn't go through with his threat to publish the e-mail addresses. The blackmail, he said, was a frustrated attempt to get 3FM to listen to him, and to have some fun. Tricking people into clicking a link leading to a video of Astley singing his popular 1987 song "Never Gonna Give You Up" is believed to have first started in 2007 at the image-based bulletin board, 4chan.

 

"It was a joke," Darkc0ke said via e-mail. "They didn't play the song. Why can't they do someone a favor, just for once?" Darkc0ke said he cracked the database using a basic SQL injection to exploit a security vulnerability. The hacker is known for breaking into databases. Last year, he stole a database containing 46,000 e-mail addresses from the Dutch magazine Autoweek.

 

While 3FM did not find it "fun" to be blackmailed and reported the incident to police, Darkc0ke said he is not concerned about the police. "They never heard anything in that case [of the Autoweek hack]. The police simply can't do much about these things."


Sign up for our Newsletters












Print |  Views: 2263   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




loek essers Loek Essers Loek Essers is a reporter for Webwereld Netherlands

Related Content

Civil liberties groups in doubt merits of upcoming child database
Civil liberties groups in doubt merits of upcoming child databaseUK department dismisses claims that child database will be used to detect crimes and evidence for prosecution
Are database admins keeping up with the database?
at ibm corp.’s information on demand conference earlier this week, i had a conversation about the future of databases with anant jhingran, the company’s vice-president and chief technology officer for information management.  
Internet under attack! Um, maybe not
someone's gotta be pretty red-faced over at symantec, which sent out an alert to its deepsight subscri
blog comments powered by Disqus